vendor:
Host Directory PRO
by:
Unknown
5
CVSS
MEDIUM
Configuration vulnerability
311
CWE
Product Name: Host Directory PRO
Affected Version From: 2.1.2000
Affected Version To: 2.1.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Change password Host Directory PRO 2.1.0
The web interface password and admin email are being stored in clear text in the HTML code of the form. This can allow an attacker to easily obtain these credentials.
Mitigation:
Store sensitive information such as passwords and email addresses in encrypted form. Use secure methods to transmit and handle sensitive data.